A network engineer needs to change, update, and control APs remotely, with real-time visibility over HTTPS. Which of the following will best allow these actions?
A. Web interface
B. Command line
C. SNMP console
D. API gateway
Show Answer
Correct Answer: A
Explanation: The requirement is remote change, update, and control of access points with real-time visibility over HTTPS. A web-based management interface (often an AP controller or cloud dashboard) natively operates over HTTPS, provides live monitoring dashboards, and allows configuration, firmware updates, and control through a browser. CLI and SNMP lack rich real-time visualization, and an API gateway is intended for programmatic integration rather than direct, interactive management.
Question 240
Which of the following source control features allows an administrator to test a new configuration without changing the primary configuration?
A. Central repository
B. Conflict identification
C. Branching
D. Version control
Show Answer
Correct Answer: C
Explanation: Branching allows an administrator to create a separate copy of the configuration or codebase to test changes independently. This testing can occur without affecting the primary (production) configuration, and successful changes can later be merged back.
Question 241
Application software systems can no longer receive updates and security patches, and continuing to use the application software might expose the system to attacks. Which of the following best describes this scenario?
A. SLA
B. Licensing
C. SIEM
D. EOL
Show Answer
Correct Answer: D
Explanation: The scenario describes software that can no longer receive updates or security patches, increasing exposure to attacks. This aligns with End of Life (EOL), where a vendor no longer provides support or updates. While End of Support (EoS) would be more precise, it is not an option, and EOL is the closest and best answer among the choices.
Question 242
A newly opened retail shop uses a combination of new tablets, PCs, printers, and legacy card readers. Which of the following wireless encryption types is the most secure and compatible?
A. WPA3
B. WPA2
C. WPA2 / WPA3 mixed mode
D. WPA / WPA2 mixed mode
Show Answer
Correct Answer: C
Explanation: The shop uses a mix of new and legacy devices. WPA3 is the most secure but is not supported by many older devices, while WPA2 alone sacrifices forward compatibility. WPA/WPA2 mixed mode is less secure because it allows deprecated WPA. WPA2/WPA3 mixed mode provides strong security for modern devices while maintaining compatibility with legacy hardware, making it the best overall choice.
Question 243
A company recently rearranged some users' workspaces and moved several users to previously used workspaces. The network administrator receives a report that all of the users who were moved are having connectivity issues. Which of the following is the most likely reason?
A. Ports are error disabled.
B. Ports have an incorrect native VLAN.
C. Ports are having an MDIX issue.
D. Ports are trunk ports.
Show Answer
Correct Answer: B
Explanation: When users are moved to previously used workspaces, the switch access ports they connect to often retain their prior configuration. The most common leftover misconfiguration is an access port assigned to the wrong VLAN. If the VLAN does not match the users’ intended network, they will experience connectivity issues. Error-disabled ports due to port security would require explicit mention of port security or violations, MDIX issues are rare with modern auto-MDIX, and trunk ports are unlikely for standard user desks. Therefore, an incorrect native/access VLAN is the most likely cause.
Question 244
A group of users cannot connect to network resources. The technician runs ipconfig from one user's device and is able to ping the gateway shown from the command. Which of the following is most likely preventing the users from accessing network resources?
A. VLAN hopping
B. Rogue DHCP
C. Distributed DoS
D. Evil twin
Show Answer
Correct Answer: B
Explanation: If a user can obtain an IP address and successfully ping the listed default gateway, local Layer 2/3 connectivity is working. The most likely remaining cause for a group of users being unable to access network resources is incorrect network configuration (such as wrong DNS, subnet, or gateway details) being handed out. A rogue DHCP server can provide valid-looking but incorrect settings, allowing gateway pings while preventing access to internal or external resources. The other options do not best fit this symptom set: VLAN hopping is an attack technique, DDoS would cause widespread disruption, and an evil twin would require a wireless scenario not described.
Question 245
A network technician is examining the configuration on an access port and notices more than one VLAN has been set. Which of the following best describes how the port is configured?
A. With a voice VLAN
B. With too many VLAN
C. With a default VLAN
D. With a native VLAN
Show Answer
Correct Answer: A
Explanation: An access port normally carries traffic for a single VLAN. The common exception is when a voice VLAN is configured, allowing the port to handle one VLAN for data and an additional VLAN for voice traffic used by IP phones. Seeing more than one VLAN on an access port best matches a voice VLAN configuration.
Question 246
Which of the following is most commonly associated with many systems sharing one IP address in the public IP-addressing space?
A. PAT
B. NAT
C. VIP
D. NAT64
Show Answer
Correct Answer: A
Explanation: Many systems sharing a single public IP address is most commonly achieved with Port Address Translation (PAT), which differentiates connections using unique port numbers. NAT is a broader concept, while VIP and NAT64 serve different purposes.
Question 247
An administrator enables DNS filtering on the firewall to block users from visiting malicious websites. Which of the following should the administrator also do? (Choose two.)
A. Disable DoH in users’ internet browsers.
B. Update NS record to point to DNS filter servers.
C. Block port 443 to the malicious websites.
D. Block port 53 to servers on the internet.
E. Disable TLS v1.3 in users’ internet browsers.
F. Implement DNSSEC for corporate records.
Show Answer
Correct Answer: A, D
Explanation: DNS filtering on a firewall relies on visibility and control of DNS queries. Disabling DNS over HTTPS (DoH) prevents users from bypassing the firewall’s DNS inspection by encrypting DNS traffic inside HTTPS. Blocking outbound port 53 to internet DNS servers ensures clients cannot use external resolvers directly and are forced to use the firewall-approved, filtered DNS service. Other options either disrupt normal operations unnecessarily or address different security goals unrelated to DNS filtering.
Question 248
An organization is struggling to get effective coverage using the wireless network. The organization wants to implement a solution that will allow for continuous connectivity anywhere in the facility. Which of the following should the network administrator suggest to ensure the best coverage?
A. Implementing additional ad hoc access points
B. Providing more Ethernet drops for user connections
C. Deploying a mesh network in the building
D. Changing the current frequency of the Wi-Fi
Show Answer
Correct Answer: C
Explanation: A mesh network uses multiple coordinated access points to provide seamless roaming and consistent signal strength throughout a facility. This design ensures continuous connectivity as users move, overcoming dead spots and obstacles better than single APs, ad hoc setups, frequency changes, or wired-only solutions.
$19
Get all 518 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.